Resource exclusion pattern `org/` silently strips resources from all `org.*` library packages
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 67/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Domain
- build-system, mobile
Research direction
Start at app/build.gradle.kts:413 and read the resource exclusion block through line 418, including the org/ and .properties patterns. Inspect how these exclusions affect dependency resources, then verify that the narrowed exclusions preserve intended exclusions without stripping unrelated org/ resources when the APK is packaged.
Written by the indexing model from the issue text.
Description
Resource exclusion pattern org/ silently strips resources from all org.* library packages
Severity: High
File: app/build.gradle.kts:413
The packaging resources exclusion block contains:
resources {
excludes += "META-INF/"
excludes += "kotlin/"
excludes += "org/"
excludes += ".properties"
}
The "org/" pattern is a prefix match against the resource path inside any dependency JAR/AAR. Any library that ships resources under org/ (e.g. org/apache/, org/xmlpull/, org/bouncycastle/ resource files, org/intellij/lang/annotations/) will have those resources silently stripped from the APK.
Why it matters
This is an overly broad exclusion that can cause runtime ClassNotFoundException, FileNotFoundException, or missing-resource crashes in any library whose resources live under org/. If the intent is to exclude only a specific package (e.g. BouncyCastle's pre-computed tables already handled at line 418), the pattern should be narrowed to the specific path like org/bouncycastle/ rather than the entire org/ tree. The same concern applies to the .properties substring match on line 414, which will exclude any file ending in .properties from any dependency — not just META-INF.
- Dominant language
- Kotlin
- Stars
- 402
- Forks
- 60
- Avg merge
- 4h 8m
- Merged PRs (30d)
- 2
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from wangzhishou/OneBox
-
`androidCompileSdkExtension = "-"` silently becomes null, hiding the intended SDK extension levelOpengood first issue
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
wangzhishou/OneBox#20 · 1 comment ·
-
[aw] Detection RunsOpenagentic-workflows
Difficulty 1/5 Under an hour Newbie friendliness 10/100
wangzhishou/OneBox#30 · 3 comments ·
-
自定义AI添加失败Openbug
Difficulty 3/5 1-2 days Newbie friendliness 40/100
wangzhishou/OneBox#29 · 1 comment ·
-
bug
Difficulty 4/5 3-5 days Newbie friendliness 48/100
wangzhishou/OneBox#23 · 1 comment ·
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 70/100
wangzhishou/OneBox#22 · 1 comment ·
All issues in wangzhishou/OneBox
Similar issues
-
go 🏃 testing 🧪
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
valkey-io/valkey-glide#7239 ·
Maintainers usually reply within 2 days
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
ethereum-lists/chains#8788 ·
Maintainers usually reply within 1 day
-
unconfirmed
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
thunderbird/thunderbird-android#11654 · 2 comments ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
tauri-apps/tauri#16173 ·
Maintainers usually reply within 2 days
-
feature
Difficulty 1/5 Under an hour Newbie friendliness 90/100
Maintainers usually reply within 1 day